Skip to content

Stealthy plist Persistence

Bypassing Security Mechanisms

macOS enforces strict permissions and integrity checks. Attackers may:
- Exploit sandboxed environments by creating plists in trusted directories like /Library/LaunchAgents (which are not typically monitored for unauthorized changes).
- Leverage Gatekeeper bypasses by signing plists with a trusted certificate (requires code signing capabilities).

Example:

# Create a signed plist in a trusted directory  
sudo plutil -insert Label "com.apple.system.plist" /Library/LaunchAgents/com.apple.system.plist  
sudo plutil -insert Program "/usr/bin/launchd" /Library/LaunchAgents/com.apple.system.plist  
sudo chown root:wheel /Library/LaunchAgents/com.apple.system.plist  
sudo chmod 644 /Library/LaunchAgents/com.apple.system.plist  

Note: The /var/db/launchd.db/ directory is not a standard location for plist files. macOS stores launchd service configurations in /Library/LaunchDaemons and /Library/LaunchAgents.